Mario Gomes and Code Audit Labs discovered that it is possible to force
Iceweasel to display the URL of the previous entered site through drag and
drop actions to the address bar. This can be abused to perform phishing
attacks.

moz_bug_r_a4 discovered that in certain cases, javascript: URLs can
be executed so that scripts can escape the JavaScript sandbox and run
with elevated privileges.

Note: We'd like to advise users of Iceweasel's 3.5 branch in Debian stable to
consider to upgrade to the Iceweasel 10.0 ESR (Extended Support Release) which
is now available in Debian Backports. Although Debian will continue to support
Iceweasel 3.5 in stable with security updates, this can only be done on a best
effort basis as upstream provides no such support anymore. On top of that, the
10.0 branch adds proactive security features to the browser.

For the stable distribution (squeeze), this problem has been fixed in
version 3.5.16-17.

For the unstable distribution (sid), this problem has been fixed in
version 10.0.6esr-1.